Crypto Long & Short: What This Year's $972 Million Crypto Hacks Actually Tell Us About Security
Key Takeaways
- •Approximately $972 million in crypto has been stolen so far in 2026, with infrastructure and human-layer failures such as compromised keys and governance exploits now driving the majority of losses rather than smart contract bugs.
- •Centralized exchange compromises involving keys, custody, and signing infrastructure accounted for 54.6% of all value lost across 191 hacks during the 2024–2025 period.
- •One protocol was audited eleven times yet still lost $128 million, illustrating that point-in-time audits alone cannot guarantee security against operational failures.
- •Bug bounty programs offer exceptionally high return on investment, with a median bounty of roughly $20,000 routinely preventing hacks that would average around $25 million in damages.
- •The Clarity Act is unlikely to pass before Congress's summer recess, reducing its chances of becoming law in 2026 as lawmakers remain divided over ethics and stablecoin yield provisions.

Crypto Long & Short: What This Year's $972 Million Crypto Hacks Actually Tell Us About Security
Most of 2026's stolen crypto is exiting through compromised keys, signers, and governance mechanisms rather than smart contract bugs, writes Mitchell Amador, founder and CEO of Immunefi. He explains why "we were audited" was never equivalent to "we are safe."
What H1's Crypto Hack Numbers Actually Tell Us About Security
By Mitchell Amador, founder and CEO of Immunefi
This month, an attacker spent approximately $4 million to drain roughly $20 million from BonkDAO's treasury. No smart contract failed. The attacker acquired enough tokens to pass a governance proposal during a low-turnout vote, and the vote executed exactly as written. The rules themselves constituted the vulnerability.
A similar scenario unfolded in June from a different angle. That month's largest loss — more than $30 million at Humanity Protocol — resulted from a private key compromised on a team member's machine, with the contract left untouched, according to the project's own account.
These incidents illustrate the shape of 2026's worst losses, with crypto losing approximately $972 million so far this year. The number of incidents continues to climb, and the funds increasingly depart through something other than a contract bug: a stolen signing key, a misconfigured verifier, or a treasury accessible to anyone who can vote their way in. The pattern aligns with broader industry data showing that infrastructure and human-layer failures — not code exploits — now drive the majority of value stolen, a shift that began accelerating as protocols hardened their smart contracts through years of audits and bug bounty programs.
Judging solely by the number of incidents, one might conclude the industry is losing ground. But examining how much has actually been stolen in total reveals a narrower, more uncomfortable pattern.
The data is precise. Across the 425 hacks Immunefi studied from 2021 to 2025, a small share of operational failures accounts for most of the value lost. In the 2024 to 2025 window, 54.6% of all value lost — across 191 hacks — can be traced to centralized exchange compromises: the keys, custody, and signing infrastructure that sit above the contract.
This does not mean the code layer is solved. Criticals are everywhere in live code. 93.9% of programs that run five years or more surface a confirmed critical, and roughly one in five confirmed reports is rated critical. The code is never finished either — every upgrade ships fresh attack surface. What has changed is that continuous, incentivized review now keeps pace with attackers on that code, which is precisely why the same model must extend further.
This is where the standard playbook runs out. An audit verifies code at a moment in time. It says nothing about who holds signing authority, how a key is stored, or what happens when a laptop is compromised. Audits are essential, and every serious team should run them, but "we were audited" was never the same as "we are safe." One protocol was audited 11 times and still lost $128 million.
What has actually hardened contract code is continuous, incentivized pressure. Through live bug bounty programs and a broader stack of monitoring and rapid response capabilities, security researchers are paid to find vulnerabilities before attackers exploit them. A roughly $20,000 median bounty routinely prevents a hack that would average around $25 million, making that payout the highest-ROI security spend a protocol can make. The model holds because it never stops, and because incentives do not decay when the org chart changes or a signer departs.
That same discipline must now cover the keys, the signers, and the rules of governance — or catastrophic losses in these areas will continue.
So does an audit make a protocol secure? On its own, no. A protocol is secure when its code, keys, people, governance, and monitoring are all treated as a live attack surface and tested continuously by researchers paid to break them first.
Headlines of the Week
By Francisco Rodrigues
This week's headlines show the crypto downturn reshaping balance sheets and market infrastructure. Strategy raised cash and began repurchasing preferred stock, while BitMEX and BitMart announced plans to close as the bear market takes its toll.
Strategy boosts cash reserve to $3.75 billion, repurchases $25 million of STRC: The firm — formerly known as MicroStrategy and the largest publicly traded corporate holder of Bitcoin — raised $544.5 million through common-stock sales and used a portion to buy back 288,930 STRC shares, while leaving its 843,775 BTC unchanged.
BitMEX, the exchange that invented perpetual swaps, is shutting down: The derivatives exchange will close on Sept. 23 after 11 years, having lost the market it pioneered to larger centralized rivals and decentralized trading platforms. The closure follows years of declining market share after settling with U.S. regulators in 2021 over charges of operating an unregistered trading platform and anti-money-laundering violations.
BitMart to shut down after nine years as BMX token crashes: The exchange will halt trading on Aug. 26 and cease operations on Jan. 31, 2027, without giving a specific reason for the closure.
Revolut hits $115 billion valuation in employee share sale: The secondary transaction lifted the crypto-friendly digital bank's valuation by 53% in less than a year, making it Europe's most valuable private company.
Clarity Act expected to miss its window before Congress' summer breaks: Senate Majority Leader John Thune said the bill — part of a broader congressional effort to establish a U.S. regulatory framework classifying digital assets as securities or commodities — was unlikely to pass before the recess, reducing its chances of becoming law in 2026 as lawmakers remained divided over ethics and stablecoin yield.
Chart of the Week
Long tail volume share on Solana rebounds past 60% as PUMP recovers
Memecoins and other long tail tokens now account for over 60% of Solana volume, up from the high 30s at the end of June. PUMP has tracked the recovery closely, rising 42% month to date.